Pravesio Consulting Private Limited ("Fin Maverick", "we", "us") operates Fin Maverick (https://www.finmaverick.com, together with https://learn.finmaverick.com and https://showdown.finmaverick.com), an online platform for finance education, NISM certification preparation, bootcamps, and practical market skills.
This Privacy Policy explains what personal data we collect, why we collect it, how we use and safeguard it, and what rights you have over it.
It is drafted to align with the Information Technology Act, 2000; the Information Technology (Reasonable Security Practices and Procedures and Sensitive Personal Data or Information) Rules, 2011; the Digital Personal Data Protection Act, 2023 ("DPDP Act") and the DPDP Rules, 2025; and the Consumer Protection Act, 2019.
By creating an account or using the platform, you agree to the practices set out here. If you do not agree, please do not use the platform.
For the purposes of the DPDP Act, Pravesio Consulting Private Limited is the Data Fiduciary. CIN: U70200HR2025PTC134374.
1. How We Approach Privacy
1.1 Design principles
We build to two rules: collect the minimum needed to run the service, and keep it only as long as there is a reason to. New features are reviewed against these rules before launch, and our existing data flows are re-checked periodically.
1.2 Scope
This policy covers the Fin Maverick website, the learning platform, the Showdown competition portal, our calculators and frameworks tools, and any email or support channel we operate. It does not cover third-party sites we link to — those have their own policies.
2. Data We Collect
2.1 Data you provide directly
- Account details — name, email address, mobile number, and a password. Passwords are never stored in readable form; we store only a salted cryptographic hash.
- Learner profile — educational background, current stage (student, working professional, career switcher), which NISM certification or bootcamp track you are targeting, target exam window, and study preferences. A profile photo is optional.
- Programme data — enrolments, cohort assignments, mentor session bookings, capstone and project submissions, internship applications, and Showdown entries.
- Payment details — billing name, billing address, GSTIN where applicable, transaction reference, and payment method type. Card numbers, CVV, UPI PINs and net-banking credentials never reach our servers; they are handled directly by our PCI-DSS compliant payment gateway.
- Communications — support tickets, emails, chat messages, feedback forms, testimonials, and survey responses.
- Verification documents — a government-issued ID, only where required to verify identity for certification support, internship placement, or dispute resolution.
2.2 Data collected automatically
- Learning and usage data — lessons opened, time spent, quiz and mock scores, accuracy by topic, flagged concepts, revision activity, session length, and progress against your track.
- Device and technical data — IP address, browser type and version, operating system, device type and identifiers, screen size, timezone, and language preference.
- Logs — server access logs, error traces, timestamps, referring and exit URLs, and API request records.
- Cookies and similar technologies — see Section 10.
- Email engagement — whether our emails are opened and which links are clicked, used to keep our communications relevant. Blocking remote images in your email client disables this.
- Account-integrity signals — coarse device and session signals used to detect credential sharing, automated scraping, and content piracy. These are used for security enforcement only and are not used to profile you commercially.
2.3 Data from third parties
- Social sign-in — if you register through Google or a similar provider, we receive your name, email address, and profile image.
- Payment gateways — transaction status and truncated card details (such as the last four digits).
- Analytics providers — aggregated and de-identified usage statistics.
2.4 Data we do not collect
We do not knowingly collect biometric identifiers, caste, religious affiliation, political opinion, genetic or health data, sexual orientation, or trade union membership. Please do not send us such information. If we receive it inadvertently, we will delete it.
We also do not ask for, and you should never send us, your demat account credentials, trading account passwords, broker login details, bank account credentials, or portfolio holdings. Fin Maverick is an education platform. We do not need this information and will not act on it.
3. Why We Use Your Data
| Purpose | Legal basis under the DPDP Act |
|---|---|
| Running, maintaining, and improving the platform | Contract; Consent |
| Personalising your learning path and recommendations | Consent; Legitimate use |
| Processing payments, enrolments, and subscriptions | Contract |
| Account administration and learner support | Contract; Legal obligation |
| Transactional email (receipts, cohort updates, service notices) | Contract |
| Marketing and promotional communication | Consent (opt-in only) |
| Mentor allocation, internship matching, and Showdown judging | Contract; Consent |
| Issuing completion certificates and verifying them on request | Contract |
| Fraud prevention, security, and anti-piracy enforcement | Legitimate use; Legal obligation |
| Detecting credential sharing and automated scraping | Legitimate use; Contract |
| Enforcing our terms and protecting our intellectual property | Legitimate use; Legal obligation |
| Internal research and content quality improvement | Legitimate use; Consent |
| Statutory compliance, tax records, and lawful government requests | Legal obligation |
Where we rely on legitimate use, we have carried out a balancing assessment. Write to help@finmaverick.com if you want the reasoning for a specific processing activity.
4. Who We Share Data With
We do not sell, rent, or trade your personal data. We share it only in the situations below.
- Service providers (sub-processors) — hosting, payment processing, email delivery, analytics, content delivery, video hosting, and helpdesk tooling. Each is bound by a written data processing agreement.
- Mentors and instructors — where you are enrolled in a mentored bootcamp or internship, the assigned mentor sees your name, track, submissions, and progress. They are bound by confidentiality obligations and may not use your data for anything outside the programme.
- Professional advisors — lawyers, auditors, and accountants, under professional confidentiality.
- Legal and regulatory authorities — where required by law, court order, or a valid statutory request, or to protect rights, property, or safety.
- Corporate transactions — in a merger, acquisition, restructuring, or asset transfer. You will be notified before your data moves.
- Enforcement — where necessary to pursue copyright infringement or content piracy, including with law enforcement or courts.
We may publish aggregated, anonymised statistics (for example, average cohort mock scores) that cannot identify any individual.
4.1 Categories of sub-processors
| Category | Purpose |
|---|---|
| Cloud hosting | Platform infrastructure and data storage |
| Payment gateway | Transaction processing (PCI-DSS compliant) |
| Email service provider | Transactional and opt-in marketing email |
| Analytics | Usage measurement and product improvement |
| CDN | Fast, secure delivery of content and assets |
| Video hosting | Lesson and recorded session playback |
| Support desk | Ticketing and learner support |
| Notification service | Browser and mobile notifications, where you opt in |
A current list naming our specific sub-processors is maintained at https://www.finmaverick.com/sub-processors and updated whenever a sub-processor is added or changed. All sub-processors are contractually required to maintain confidentiality, apply appropriate security, and delete or return data on termination.
4.2 Third-party SDKs
Our platform may include third-party software development kits for analytics, crash reporting, and performance monitoring. We configure these to minimise data collection and to disable advertising identifiers wherever the SDK permits it.
5. How Long We Keep Data
| Data | Retention period | Reason |
|---|---|---|
| Account data | Life of the account + 3 years | Limitation period for disputes |
| Transaction and invoice records | 8 years | Income Tax Act; GST Act |
| Learning and usage data (identified) | 3 years | Service improvement; progress history |
| Learning data (anonymised) | Indefinite | Research and benchmarking |
| Certificates issued and verification records | 7 years | Certificate verification requests |
| Support communications | 3 years | Dispute resolution and quality review |
| Security and audit logs | 5 years | IT Act; security compliance |
| Account-integrity signals | Life of the account + 1 year | Fraud and piracy detection |
| Piracy investigation records | Conclusion of proceedings + 3 years | Copyright enforcement |
| Email engagement data | 1 year | Communication optimisation |
| Records of consent | Life of the account + 3 years | Proof of consent |
Once the period ends, data is securely deleted or irreversibly anonymised within 30 days, unless a legal hold or statutory obligation requires otherwise.
6. How We Protect Your Data
We apply industry-standard controls, including:
- encryption in transit (TLS 1.2 or higher) and at rest;
- role-based access on a least-privilege basis;
- multi-factor authentication for all administrative access;
- periodic vulnerability assessment and penetration testing;
- monitoring and alerting on access and error logs;
- encrypted, geographically separated backups;
- a secure development lifecycle with code review before release;
- confidentiality agreements for employees, mentors, and contractors;
- data protection training for anyone with access to learner data; and
- documented incident response and business continuity procedures.
No system is completely secure. We cannot guarantee absolute security, but we take commercially reasonable measures and review them regularly.
7. Breach Notification
If a personal data breach occurs, we will:
- notify the Data Protection Board of India as required under the DPDP Act and the DPDP Rules, 2025;
- notify affected users by email or in-platform notice, describing the nature of the breach, the data involved, the likely consequences, and what we are doing about it;
- report qualifying incidents to CERT-In within the timeline set by the applicable CERT-In directions in force; and
- maintain an internal breach register recording each incident, its impact, and the remedial action taken.
8. Your Rights
Under the DPDP Act, 2023, you may:
- Access — obtain a summary of the personal data we hold about you and how it is processed.
- Correct — have inaccurate or incomplete data corrected or updated.
- Erase — request deletion, subject to the statutory retention periods in Section 5.
- Withdraw consent — at any time. This does not affect processing already carried out, and may limit or end your access to parts of the service.
- Port your data — receive your learning records in a structured, machine-readable format (JSON or CSV) where technically feasible.
- Nominate — appoint someone to exercise your rights in the event of your death or incapacity.
- Complain — raise a grievance with our Grievance Officer, and escalate to the Data Protection Board of India if unresolved.
Email help@finmaverick.com to exercise any of these. We will respond within 7 working days of verifying your identity. Complex requests may take up to 30 days, and we will tell you if that applies.
8.1 Opting out of marketing
You can opt out at any time by:
- clicking "unsubscribe" in any marketing email;
- changing your communication preferences in account settings;
- emailing help@finmaverick.com with the subject "Unsubscribe"; or
- turning off notifications in your browser or device settings.
We action opt-outs within 48 hours. Transactional messages — receipts, cohort schedules, security alerts, policy changes — are not marketing and continue while your account is active.
9. Users Outside India
9.1 Cross-border transfers
Your data is primarily stored in India. Where a cloud provider or sub-processor processes it elsewhere, we ensure DPDP Act compliance, appropriate contractual safeguards, and that the destination is not a restricted jurisdiction notified by the Central Government.
9.2 EU/EEA users
If you access Fin Maverick from the European Economic Area, the GDPR gives you additional rights: to complain to your local supervisory authority; to data portability; to object to processing based on legitimate interest or direct marketing; not to be subject to automated decisions producing legal or similarly significant effects; and to erasure under Article 17. Our legal bases are consent (Art. 6(1)(a)), contract (Art. 6(1)(b)), legitimate interest (Art. 6(1)(f)), and legal obligation (Art. 6(1)(c)). Transfers out of the EEA rely on the Standard Contractual Clauses approved by the European Commission.
9.3 California residents
Under the CCPA and CPRA you have the right to know what personal information we collect, use, and disclose; to delete it; to correct it; to opt out of any sale or sharing (we do not sell personal information); and not to be discriminated against for exercising these rights. Email help@finmaverick.com with "CCPA Request" in the subject line. We respond within 45 days.
10. Cookies and Tracking
| Type | What it does | Can you disable it? |
|---|---|---|
| Essential | Login sessions, security, load balancing | No — the platform will not work |
| Analytics | Usage patterns and performance, anonymised | Yes |
| Preferences | Language, display mode, study settings | Yes |
| Marketing | Campaign measurement, set only with consent | Yes |
Manage your choices through our consent banner or your browser settings.
10.1 Do Not Track — we do not currently respond to browser "Do Not Track" signals. If a uniform standard emerges, we will update this policy.
10.2 Notifications — if you enable browser or push notifications, we store a device token to deliver them. It is deleted when you turn notifications off. It is not shared with anyone except our notification delivery provider.
11. Children
Fin Maverick is not intended for anyone under 16. We do not knowingly collect data from children under 16. If we discover that we have, we will delete it within 72 hours. If you believe a child has provided us data, contact help@finmaverick.com.
12. Automated Processing
We use algorithms to recommend content, adapt your learning path, and flag suspected fraud or piracy. These do not produce legal or similarly significant effects on you. If we ever introduce an automated decision that does, we will tell you and offer human review within 7 working days of your request.
13. Data Protection Impact Assessments
We carry out DPIAs where processing is likely to pose a high risk to your rights, including for large-scale behavioural data processing, account-integrity monitoring, significant new features, and transfers to new jurisdictions. DPIA records are held internally and available for regulatory inspection.
14. Grievance Officer
As required under the IT Act, the SPDI Rules, and the DPDP Act:
- Name: Niyati Arora
- Designation: Grievance Officer
- Email: help@finmaverick.com
- Phone: +91 98101 18573
- Address: Flat No. B-3/103, Sahara Grace, M.G. Road, Gurgaon – 122002, Haryana
We acknowledge complaints within 48 hours with a tracking reference and aim to resolve them within 7 working days. If you are not satisfied, you may use our internal appeal process, and thereafter escalate to the Data Protection Board of India.
15. Changes to This Policy
We may revise this policy. For material changes we will give at least 15 days' notice by email or in-platform notification. Continuing to use the platform after the effective date means you accept the revised policy. Earlier versions are archived at https://www.finmaverick.com/privacy-policy/archive.
16. Contact
Pravesio Consulting Private Limited Registered Office: Flat No. B-3/103, Sahara Grace, M.G. Road, Gurgaon – 122002, Haryana CIN: U70200HR2025PTC134374 Email: help@finmaverick.com Web: https://www.finmaverick.com
